Microsoft Exchange Online for Security Operations release notes
Summarize
Summary of Microsoft Exchange Online for Security Operations release notes
The Microsoft Exchange Online for Security Operations application integrates Exchange Online email search and management capabilities within ServiceNow Security Incident Response. It enables security analysts to configure phishing threat searches, manage suspicious emails, and maintain audit trails, enhancing incident investigation and response workflows.
Show less
Key Features
- Configurable search criteria for phishing threats based on sender, recipient, and subject fields.
- Email search results include full message details, supporting special characters in subject lines.
- Notification emails alert analysts when large or lengthy email searches complete, including matched message counts.
- Status tracking for individual messages to indicate if recipients have read or deleted suspicious emails.
- Optional approval workflows to control deletion of suspicious emails, ensuring compliance and oversight.
- Comprehensive audit trails logged in security incident work notes covering delete requests and counts.
- Security tagging of incidents to record initiation and completion of email search and delete workflows.
- Support for Multi-Factor Authentication (MFA) at the tenant level to enhance security.
- Enhanced error handling and logging, including diagnostics tests and debug level configuration for troubleshooting integration issues.
- Migrated workflows to ServiceNow Flow Designer for improved automation management.
- Support for non-ANSI characters and Federal customer-specific Graph URL configurations.
- MID Server routing enhancements allowing selective routing of integration searches to capable MID Servers, improving performance and reliability.
- Strict Read-Only enforcement on dictionary-level fields to prevent unauthorized changes across UI, scripts, and integrations.
Recent Fixes and Improvements
- Resolved issues where email searches by subject keywords returned no results due to exact match query logic; updated to keyword matching.
- Comments entered during rejection of email requests are now correctly reflected in associated security incidents.
- Fixed handling of email search failures related to special characters and quotation marks in subject queries.
- Improved PowerShell error logging to provide detailed stack traces for troubleshooting.
- Removal of unsupported email fields from search criteria to streamline and stabilize searches.
- Addressed misconfigurations in access control lists (ACLs) within the application plugin.
- Enhanced encoding of search queries to comply with Microsoft Graph API changes, preventing empty search results.
- Inclusion of junk folder emails in phishing email search and delete actions.
- Automated creation of work notes and security tags when searches or deletions fail, including notifications for OAuth credential expirations.
- UI and configuration improvements, including button alignment and application tile updates.
What ServiceNow Customers Can Expect
By leveraging this application, security operations teams gain streamlined and robust capabilities to detect, investigate, and remediate phishing and other email-based threats directly within ServiceNow. Enhanced search accuracy, detailed audit trails, and configurable approval processes support compliance and operational efficiency. Improved integration stability, security enhancements like MFA support, and troubleshooting tools ensure reliable and secure operation aligned with enterprise security requirements.
Version history for the Microsoft Exchange Online for Security Operations application on the ServiceNow Store.
Version history
- Version 10.7.4 - June 2026
- Fixed: Email search by subject line keywords returned no results because the Hunting API query used exact match (==) instead of keyword match (has) for the Subject field.
- Version 10.7.3 - March 2026
- Fixed:
- Comments entered while rejecting email requests are now correctly reflected in the associated Security Incident Response.
- Email search requests no longer fail when the subject query contains quotation marks.
- Fixed:
- Version 10.7.2 - January 2026
- Fixed: Fixed an incorrect “email search is still running” message shown during the deletion approval step.
- Version 10.7.0 - December 2025
- New: Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes. This update ensures the server consistently enforces read-only behaviour across all UIs, scripts, and integrations.
- Version 10.6.5 - May 2025
- Fixed: Remove/hide unsupported email fields from the email search criteria.
- Version 10.6.3 - February 2025
- Changed: Migrated workflows to flow designer.
- Version 10.6.2 - March 2024
- Fixed:
- Supports non-ANSI characters in Threat-Hunting API query.
- Supports Graph URL configuration for Federal customers.
- Fixed:
- Version 10.5.5 - December 2023
- Fixed: Addressed the misconfiguration of table/field ACLs within the com.snc.secops.ms.exchange.online plugin.
- Version 10.5.2 - November 2021
- Fixed:
- Added additional password-related policies.
- Failure of Email search, if the Exchange Module V2 is not present in MID server.
- Termination of Email search workflow because of an activity count limit.
- Improved PowerShell error logging for proper stack trace if an error is seen in the processing.
- Fixed:
- Version 10.5.0 - August 2021
- New: Support for Multi Factor Authentication (MFA) at the Tenant Level
- Fixed: Ability to delete emails from the email server through the UI action - 'Delete Emails from Exchange Online' that is present under the Email Search Results section
- Version 10.4.2 - February 2021
- Fixed: This release includes a fix from double encoding a query to single encoding, to address the functionality change by Microsoft Graph API. Microsoft Graph API has modified their functionality which causes no results to appear when running a query. For example, if the subject contains a space, then results don't appear. Only the count of emails is returned. A system property sn_sec_ms_ex_on.single_encode has been added to specify the use of single encoded or double encoded search queries. It defaults to single encoded queries.
- Version 10.4.1 - December 2020
- New:
- A security tag is applied to a security incident, and a work note is created when the search and delete action fails.
- An error email notification is sent to a group, and a work note is created when the Microsoft Exchange Online OAuth credentials expire.
- Changed:
- Email Search and delete action includes junk folder for matching phishing emails and deletes them.
- Email Search Result record is created when the search and delete action fails.
- New:
- Version 10.3.2 - June 2020
- New: Additional setting Email Result Threshold for Approvals
- Changed: Threshold configuration for Request Delete Approvals
- Version 10.0.1 - March 2020
- New:
- Introduced troubleshooting capabilities by adding diagnostics tests that provide the ability to isolate issues with the integration
- New system property added to increase debug level logging
- Fixed: UI alignment of buttons present on the Microsoft Exchange Online configuration settings
- New:
- Version 8.0.3 - September 2019
- Fixed:
- Improved error handling for unsupported characters
- Fixed support for valid special characters such as apostrophes, double quotations, and colons (PRB1358086)
- Version 8.0.2 - August 2019
- New:
- Additional Settings parameters for Maximum Search Duration and Search Completion Notification
- MID Server Routing Changes: Provides ability to selectively route the integration searches to designated MID Servers that have the necessary MID Server capabilities enabled (instead of all MID Servers)
- Changed:
- Application tile configuration modifications: With the MID Server routing changes in this update, it is no longer necessary to designate a MID Server during the initial authentication set-up. In addition, there is a new status indicator for the MID Server Ready that will distinguish an authentication credential problem from a MID Server availability issue.
- Approval rejection notes are now posted to the work notes when an approval is rejected and the approver provides a reason to the SOC analyst.
- Email search results now contain the full message details, including the subject field that was missing with some platform versions.
- Fixed: Searches were previously not able to retrieve matching messages when the subject contained special characters, such as #. Special characters are now supported in the email subject parameter for searches.
- New:
- Version 5.0.0 - March 2019
- Configure search criteria for phishing threats in Security Incident Response based on combinations of the sender, recipient, and subject fields on email messages.
- For large and lengthy email searches, the security incident analyst is notified via email when a search is successfully completed, along with the number of matched messages.
- Status for individual messages informs you if recipients have read or deleted suspicious emails.
- If configured, optional approval processes ensure that suspicious emails are not deleted without prior approval.
- A complete audit trail for delete requests that includes the number of deleted emails is logged in the work notes of security incidents.
- If tagging is configured, security tags record when email search and delete workflows are initiated and successfully completed on security incidents.